Apache DolphinScheduler是美国阿帕奇(Apache)基金会的一个分布式的基于DAG可视化的工作流任务调度系统。 Apache DolphinScheduler 3.2.1版本存在输入验证错误漏洞,该漏洞源于存在输入验证不正确漏洞,经过身份验证的用户可以导致任意的、未受沙箱限制的JavaScript在服务器上执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache DolphinScheduler | 0 ~ 3.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-41888 | Apache Answer: The link for resetting user password is not Single-Use | |
| CVE-2024-41890 | Apache Answer: The link to reset the user's password will remain valid after sending a new | |
| CVE-2024-30188 | Apache DolphinScheduler: Resource File Read And Write Vulnerability |
No comments yet